Heap-based buffer overflow in Microsoft 365 Apps for Enterprise and Microsoft Office - CVE-2026-69285
Published: September 8, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to a heap-based buffer overflow in Microsoft Office when opening a specially crafted file. A remote attacker can provide a specially crafted file to execute arbitrary code.
The Preview Pane is an attack vector, and user interaction is required.
Affected software
Microsoft Office
How to mitigate CVE-2026-69285
Microsoft Office - addressed in versions 16.0.5569.1000, 16.0.10417.20207, 16.0.14334.20906, 16.0.17932.20976